Python 3.11 Open CVE Resolution?

1 view
Skip to first unread message

Tim Daneliuk

unread,
May 4, 2026, 1:02:51 PM (9 days ago) May 4
to FreeBSD Mailing List
A lot of port upgrades are failing because of open CVEs on Python 3.11 on 13.5-STABLE.

Do we have a likely ETA for resolution? I prefer not to disable vulnerability checking.

TIA

Michael Sierchio

unread,
May 4, 2026, 1:18:28 PM (9 days ago) May 4
to FreeBSD Mailing List
On Mon, May 4, 2026 at 1:02 PM Tim Daneliuk <thron...@gmail.com> wrote:
>
> A lot of port upgrades are failing because of open CVEs on Python 3.11 on 13.5-STABLE.
>
> Do we have a likely ETA for resolution? I prefer not to disable vulnerability checking.

By resolution do you mean availability of a point release for Python,
such as 3.11.15?

Tim Daneliuk

unread,
May 4, 2026, 7:38:46 PM (9 days ago) May 4
to FreeBSD Mailing List
On 5/4/26 16:34, Tim Daneliuk wrote:
> Yes.  This has not appeared in ports yet so far as I know.

I should correct this. 3.11.15 is in the ports, but the current .2 subversion is still
shown vulnerabilities.

This is preventing all manner of other ports updates.

Tim Daneliuk

unread,
May 11, 2026, 8:53:38 PM (2 days ago) May 11
to FreeBSD Mailing List
Nevermind. I managed to somehow miss that 13-stable was EOL. A move to 14-stable
on a few servers made everything happy again (but the CVEs are still not resolved).

D'Oh ...

Reply all
Reply to author
Forward
0 new messages